When an AI Tool Harms You, Who’s Actually Liable?
When an AI Tool Harms You, Who's Actually Liable?
Picture the ordinary version of this. You ask an AI assistant a question that actually matters - about a refund policy, a dose, a tax rule, a contract clause - and it answers with the fluent confidence these tools always have. You act on it. It was wrong. Now you are out of pocket, or worse. Whose problem is that?
The answer-first version is unsatisfying but honest: it depends on where you live and who you sue, and almost every party involved has arranged things so the answer isn’t “us.” There is, in most places, no single law that says “here is who pays when an AI gets it wrong.” Instead there is a scramble to fit a new kind of tool into old boxes - contract, consumer protection, negligence, product liability - while the companies that build these systems write terms designed to keep the box firmly shut.
That is worth understanding before you need it, because the gap between how these products are marketed - capable, authoritative, ready for real work - and how their contracts describe them - experimental, unwarranted, use at your own risk - is where liability quietly lives. “The chatbot did it” is not a defence.
The Law of AI Liability
Start with the case everyone cites, because it is refreshingly concrete. In Moffatt v. Air Canada, decided by British Columbia's Civil Resolution Tribunal in early 2024, a grieving customer asked the airline's website chatbot about bereavement fares. The bot told him he could book now and claim the discount retroactively within 90 days. That was wrong; the airline's actual policy, sitting on a different page, said no such thing. When he tried to claim, Air Canada refused. The airline's defence became briefly famous: it argued, in effect, that the chatbot was “a separate legal entity that is responsible for its own actions.” The tribunal did not buy it. Air Canada was responsible for all the information on its website, it held, whether that information came from a static page or a chatbot, and it owed the customer a duty to take reasonable care that its representations were accurate. The company was ordered to honour the fare and pay damages.
The principle is simple and portable: if your business puts an AI in front of customers, what the AI says is what your business said.
The Harder Frontier: Product Liability
The harder frontier is product liability, and here the landmark is Garcia v. Character Technologies in the United States. The suit was filed in October 2024 by a mother after the death of her fourteen-year-old son, and it named the chatbot maker, its founders and Google. We report it soberly and only for what the court actually did, because the underlying facts are a tragedy, not a talking point.
What the court did was significant. In an early 2025 ruling, a federal judge in the Middle District of Florida denied the companies' motion to dismiss, rejected a First Amendment argument that a chatbot's outputs were protected speech, and - crucially - treated the app as a “product” for the purposes of product-liability law, allowing wrongful-death, negligence and product-liability claims to proceed. That was a decision about whether the case could go forward, not a final verdict that the company was liable, and the matter was later resolved through a settlement.
The Terms You Clicked Past
Now the part almost nobody reads, which is precisely where the companies do their work. Open the terms of service for a major AI provider and you will find a familiar wall. The service is provided “as is.” Warranties - including the implied ones that the thing is fit for its purpose or of satisfactory quality - are disclaimed to the maximum the law allows. Liability for indirect, incidental or consequential damages is excluded outright. And total liability is capped at a number that is, from the user's side, close to symbolic.
Anthropic's consumer terms, for instance, cap its total liability at the greater of the amount you paid in the six months before the claim and $100, while excluding indirect and consequential damages. OpenAI's provide the service “as is,” disclaim warranties and exclude the same broad categories of damages. This is not unusual language for software, and that is the point: the industry has borrowed the liability posture of a free web app and applied it to tools it simultaneously markets as good enough to replace human workers and to advise you on things that matter.
The Harms That Never Reach a Courtroom
Moffatt and Garcia are the cases that made headlines, but they are the exceptions that prove the rule: most AI harm is too ordinary and too small to litigate, which is exactly why the terms are written the way they are. Think of the everyday versions. A coding agent, run unattended, deletes or mangles work you can't easily reconstruct. A hallucinated citation or fact makes it into something you file or send, and the embarrassment - or the professional sanction - is yours, not the model's. An AI summary of a policy is confidently wrong and you act on it. A chatbot says something defamatory about a named person, and the question of who published it is genuinely unsettled. None of these arrives with a clean defendant and a big number attached, so almost none of them ever becomes a case.
Europe Pulled Up a Ladder It Had Lowered
For a moment it looked as if Europe would write the missing rule. The proposed AI Liability Directive was meant to do something specifically useful for ordinary claimants: ease the burden of proving that an opaque AI system caused their harm, because “the model did something I can’t inspect” is a miserable thing to have to prove. In 2025 the European Commission withdrew the proposal, citing a lack of agreement and a broader push to simplify digital rules. The withdrawal was formalised later that year.
What Actually Decides Whether You Can Recover
Pull the threads together and a rough checklist emerges. Whether you have a real claim, rather than a grievance, tends to turn on:
- Was there a relationship the law recognises? A paying customer of a business that used AI to serve you (as in Moffatt) is on far firmer ground than someone who got a bad answer from a free chatbot they used casually.
- Does consumer-protection law apply? In many countries it overrides the fine print, so a “we’re not liable for anything” clause may not survive contact with a tribunal.
- Can the AI be framed as a “product”? If so, product-liability rules - and, in the EU from December 2026, strict liability - may attach, sidestepping the need to prove fault.
- Did the company make specific promises? A concrete representation about accuracy or safety is easier to hold them to than a vague marketing vibe.
- Where are you, and where are they? Jurisdiction, arbitration clauses and which country's consumer law applies can decide the case before the merits are even reached.
The Fair Case for the Other Side
Steel-man the companies, because their position is not pure evasion. Large language models are probabilistic; they will sometimes be confidently wrong no matter how much work goes in, and that unreliability is not fully fixable today. Disclaimers and caps are standard across software precisely because a tool used in a million unforeseeable ways cannot underwrite every outcome. And there is a real risk that clumsy, over-broad strict liability could chill genuinely useful products or push them out of smaller markets.
What to Do While the Law Catches Up
Practical, boring, effective. For anything that carries real stakes - money, health, legal exposure - treat an AI answer as a lead to verify against a primary source, not as advice you can bank. Keep records: the prompt, the answer, the date, a screenshot. If a business's own chatbot gives you a commitment, that commitment may well bind the business, as Moffatt shows - so save it. Know that in many places consumer law is on your side more than the terms suggest, and that a confident “we’re not liable” is an opening position, not a verdict. And watch the direction of travel: for all the disclaimers, courts and legislators are slowly deciding that when these systems cause harm, “the AI did it” is not the end of the conversation. It is the start of one.
Comments
No comments yet. Start the discussion.